Skip to content

kernel CVE-2022-33741

Moderate
rpkelly published GHSA-c3cw-2p8m-3568 Jul 29, 2022

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.9.0

Patched versions

1.9.0
kernel-5.15 (bottlerocket)
< 1.9.0
1.9.0
kernel-5.4 (bottlerocket)
< 1.9.0
1.9.0

Description

Block and network PV device frontends don’t zero memory regions before sharing them with the backend, and the granularity of the grant table doesn’t allow sharing less than a 4K page. This leads to unrelated data residing in the same 4K page as data shared with a backend being accessible by that backend.

Severity

Moderate

CVE ID

CVE-2022-33741

Weaknesses

No CWEs